An attacker got into some of Andover’s computer systems during the Andover cyberattack in August; Town officials confirmed Thursday, though they cannot yet say whether any data was taken.
“The Town has identified unauthorized access to certain systems and is continuing to determine the nature, scope, and sensitivity of any data that may have been accessed or acquired,” Chief Communications Officer Phil Geoffroy said in written answers to Andover News.
Some reviewed material appears routine or publicly available, he said, but the full data set remains uncharacterized.
What Is Known About the Andover Cyberattack
It is the Town’s clearest admission that the Aug. 13 cyberattack on Andover reached its systems, though not proof of copying, removal or publication.
Geoffroy did not identify the systems, say whether they belonged to the municipality or Andover Public Schools, or give a completion date. Investigators must check any accessed data for personally identifiable information, he said. Officials first secured and restored the network, reconnecting equipment, even printers, across municipal and school offices. Another update will come “if/when appropriate.”
Town Counsel Doug Heim told the Select Board Sept. 28 that it was unclear whether state-protected information was involved.
Investigators and Ransom Questions
The Town hired law firm Constangy, Brooks, Smith & Prophete and cybersecurity firm Vector3 on the evening of Aug. 13. Vector3 is tracing how the attacker entered, reconstructing the attacker’s activity, assessing whether data was accessed or removed, and helping monitor more than 3,000 devices.
On ransom demands or negotiations, Geoffroy said only that the Town “did not make or authorize any payments in connection with this incident.” Vector3’s agreement allowed up to $3,000 for possible communication with the attacker and monitoring of negotiation channels for up to 60 days, though its use is unconfirmed.
No culprit has been named. On Aug. 30, a ransomware group called WallStreet listed Andover as a purported victim on a dark-web site, which proves neither responsibility nor data theft.
Geoffroy would not name agencies notified: “The Town is coordinating with appropriate legal, forensic, and governmental partners as required and cannot comment on any law enforcement-related aspects of the event at this time.”
If Chapter 93H, the Massachusetts breach law, applies, the Town must notify the Attorney General’s Office, state regulators and affected people. That office had received no notice as of Sept. 22.
Who Pays for the Cyberattack on Andover?
An Oct. 5 public records appeal response said the Town had received no bills and incurred no costs beyond its insurance policy, seemingly conflicting with agreements estimating at least $39,605 in initial Vector3 and Constangy work. The insurer pays them directly, Geoffroy said.
“Subject to the limits of our policy, Andover will bear no additional costs for these contractors and bills will be paid by our insurer,” he said.
The policy covers up to $1 million for several categories of cyber expenses and $100,000 for cyber-extortion, with a $10,000 retention on most categories. The Town did not address overtime, replacement equipment, security upgrades or the retention.
Town Defends Its Preparedness
“Based on what is currently known, the Town does not believe this incident reflects a lack of investment in information technology or incident preparedness,” Geoffroy said. He credited past spending on technology, cyber insurance and response planning with helping contain the attack, restore services and coordinate quickly, noting longer disruptions elsewhere.
The Andover cyberattack disrupted the municipal and school network for four days, with some restoration continuing afterward. Shared drives returned fully Aug. 21, and VPN access stayed down during its rebuild. Public safety, municipal buildings, phones and Town-operated utilities kept operating.






































